Skip to content
Content type · 1,282 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1101–1150 of 1,282 sort newestlargest fineoldest
€36,000 Banco Bilbao Vizcaya Argentaria, S.A.: Non-compliance with general data processing principles The Spanish DPA (AEPD) fined the financial and credit institution Banco Bilbao Vizcaya Argentaria, S.A. (BBVA) with a fine in the amount of EUR 36,000. The BBVA asked the data… SPAIN ·aepd ·Art. 5 Personal Data Controllers Insurance Dec 21, 2020
€525,000 Locatefamily.com: Non-compliance with general data processing principles The Dutch DPA (AP) has imposed a fine of EUR 525,000 on Locatefamily.com. Locatefamily.com is a platform where people can search for the contact information of family members they… THE NETHERLANDS ·AP ·Art. 27 Representatives IP Address Personal Data Dec 20, 2020
€40,000 Miropass S.r.l.: Insufficient legal basis for data processing The Italian DPA (Garante) fined Miropass S.r.l. EUR 40,000. Miropass is the provider of the TuPassi booking system, which among others has been used by the Municipality of Rome… ITALY ·Garante ·Art. 5, 6, 9 +1 Storage Limitation Healthcare Retention Period Dec 17, 2020
€500,000 Roma Capitale (Rome Municipality): Non-compliance with general data processing principles The Italian DPA (Garante) fined the municipality of Rome EUR 500,000 for the unlawful processing of users' and employees' personal data. The municipality of Rome had been using… ITALY ·Garante ·Art. 5, 13, 14 +2 Integrity and Confidentiality Principle IP Address Education Dec 17, 2020
€100,000 Banca Transilvania SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA (ANSPDCP) fined Banca Transilvania SA EUR 100,000 for violations of Art. 5 (1) f) GDPR, Art. 32 (1) GDPR and Art. 32 (2) GDPR. It was found that the bank… ROMANIA ·ANSPDCP ·Art. 5, 32 Integrity and Confidentiality Principle Data Breaches Security Dec 17, 2020
€4,000 Comune di Santo Stefano Belbo: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 4,000 on the municipality of Santo Stefano Belbo. The reason for this was that the controller had published two documents on a… ITALY ·Garante ·Art. 5, 6 Personal Data Education IP Address Dec 17, 2020
€10,000 Comune di Luino: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 10,000 on the municipality of Luino. The controller had published a document containing personal data of a local council member. In… ITALY ·Garante ·Art. 5, 6, 37 Public Authority IP Address Controllers Dec 17, 2020
€100,000 Azienda Unità Sanitaria Locale Toscana Sud Est: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 100,000 on Azienda USL Toscana Sud Est. The controller is a company in the healthcare sector that, among other things, launched the… ITALY ·Garante ·Art. 5, 13, 14 +4 Health Data DPIA Healthcare Dec 17, 2020
€97,150 HUNGARY DPA: Insufficient legal basis for data processing The Hungarian DPA (NAIH) imposed a fine of EUR 97,150 against a credit institute. Two parents contacted the Hungarian DPA regarding the processing of personal data by their credit… NAIH ·Art. 5, 6, 9 +1 ·Insufficient legal basis for data processing Health Data Personal Data Healthcare Dec 16, 2020
€10,000 Online Services: Insufficient fulfilment of information obligations The Spanish DPA (AEPD) fined the operator of the online store banderacatalana.cat. EUR 10,000 for a violation of Art. 13 GDPR. The operator stated on its website privacy notices… SPAIN ·aepd ·Art. 6, 8, 13 IP Address Personal Data Processing Agreement Dec 15, 2020
€22,200 Budapesti Műszaki és Gazdaságtudományi Egyetem (Budapest University of Technology and Economics): Insufficient legal basis for data processing The Hungarian DPA (NAIH) imposed a fine of EUR 22,200 against the Budapest University of Technology and Economics. NAIH finds that the controller unlawfully processed personal… HUNGARY ·NAIH ·Art. 5, 6, 9 +2 Education Personal Data Controllers Dec 10, 2020
€10,000 SPAIN DPA: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine of 10,000 EUR on a company for violating Art. 5 GDPR. The company sent an e-mail to a third party with the dismissal and settlement document… aepd ·Art. 5 ·Non-compliance with general data processing principles Personal Data IP Address Processing Agreement Dec 9, 2020
€243,800 Västerbotten Region: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Västerbotten Region SEK 2,500,000 (EUR 243,800) for failing to implement adequate technical and organizational measures to… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Healthcare Healthcare Security Dec 3, 2020
€243,800 Östergötland Region: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Östergötland Region SEK 2,500,000 (EUR 243,800) for failing to implement adequate technical and organizational measures to… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Health Data Healthcare Dec 3, 2020
€1.2M Aleris Sjukvård AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Aleris Sjukvård AB SEK 12,000,000 (EUR 1,168,000) for failing to implement adequate technical and organizational measures to… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Healthcare Security Healthcare Dec 3, 2020
€18,840 Municipality of Indre Østfold: Insufficient technical and organisational measures to ensure information security The Norwegian DPA (Datatilsynet) imposed a fine in the amount of NOK 200,000 (EUR 18,840) on the municipality of Indre Østfold. Datatilsynet found that a student file containing… NORWAY ·Datatilsynet ·Art. 6, 32 Education Personal Data Public Authority Dec 3, 2020
€390,100 Karolinska University Hospital of Solna: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Karolinska University Hospital of Solna SEK 4,000,000 (EUR 390,100) for failing to implement adequate technical and… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Health Data Healthcare Dec 3, 2020
€1.5M Aleris Sjukvård AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Aleris Sjukvård AB SEK 15,000,000 (EUR 1,463,000) for failing to implement adequate technical and organizational measures to… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Health Data Security Healthcare Dec 3, 2020
€2.9M Capio St. Göran AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Capio St. Göran AB SEK 30,000,000 (EUR 2,900,000) for failing to implement adequate technical and organizational measures to… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Healthcare Healthcare Security Dec 3, 2020
€341,300 Sahlgrenska University Hospital: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Sahlgrenska University Hospital SEK 3,500,000 (EUR 341,300) for failing to implement adequate technical and organizational… SWEDEN ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Healthcare Health Data Security Dec 3, 2020
€10,000 Losada Advocats S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) imposed a fine on Losada Advocats S.L. for sending an e-mail to dozens of recipients without putting them on the Blind Carbon Copy (BCC) list, thus… SPAIN ·aepd ·Art. 5, 32 IP Address Processing Agreement Security Dec 2, 2020
€100,000 Apotheka e-apteek: Insufficient legal basis for data processing The Estonian DPA (Andmekaitse Inspektsioon) fined three online pharmacies EUR 100,000 each for processing personal data without the consent of the data subjects. The data in… ESTONIA ·AKI ·Art. 5, 6 Healthcare IP Address Personal Data Dec 1, 2020
€100,000 Südameapteegi e-apteek: Insufficient legal basis for data processing The Estonian DPA (Andmekaitse Inspektsioon) fined three online pharmacies EUR 100,000 each for processing personal data without the consent of the data subjects. The data in… ESTONIA ·AKI ·Art. 5, 6 Healthcare Consent IP Address Dec 1, 2020
€100,000 Azeta.ee e-apteek: Insufficient legal basis for data processing The Estonian DPA (Andmekaitse Inspektsioon) fined three online pharmacies EUR 100,000 each for processing personal data without the consent of the data subjects. The data in… ESTONIA ·AKI ·Art. 5, 6 Healthcare Consent IP Address Dec 1, 2020
€1,200 Private Individual: Non-compliance with general data processing principles The Spanish DPA (AEPD) imposed a fine in the amount of EUR 1,200 on a private individual for impersonating a third party on the social networks Tinder and WhatsApp by using images… SPAIN ·aepd ·Art. 5 IP Address Personal Data Consent Nov 27, 2020
€10,000 Reti Televisive Italiane S.p.a.: Non-compliance with general data processing principles The television station broadcasted a documentary about the link between emissions from a local ceramics plant and health problems in the population, in which the person… ITALY ·Garante ·Art. 5 Healthcare IP Address Telecommunications Nov 26, 2020
€40,000 Miraclia Telecomunicaciones S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 40,000 on Miraclia Telecomunicaciones S.L. for violating Articles 6, 13 and 14 of the GDPR. Miraclia Telecomunicaciones S.L. is the… SPAIN ·aepd ·Art. 6, 13, 14 Recipient IP Address Personal Data Nov 25, 2020
€19,500 Gnosjö Municipality: Insufficient legal basis for data processing The Swedish DPA imposed a fine on the municipality of Gnosjö for illegal video surveillance in a care home for persons with certain functional disabilities. SWEDEN ·Art. 5, 6, 13 +2 ·Insufficient legal basis for data processing Video Surveillance Monitoring Healthcare Nov 25, 2020
€20,000 Burgo Group S.p.A: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 20,000 on the company for non-compliant practices. Thus, for example, the personnel director forwarded an e-mail conversation… ITALY ·Garante ·Art. 5, 13 Personal Data IP Address Employees Nov 23, 2020
€2.3M Carrefour France: Non-compliance with general data processing principles The French DPA (CNIL) fined Carrefour France EUR 2,250,000 for several violations of data protection regulations, including the GPDR. During its investigation, the CNIL found that… CNIL ·Art. 5, 12, 13 +5 ·Non-compliance with general data processing principles IP Address Processing Agreement Personal Data Nov 18, 2020
€28 HUNGARY DPA: Non-compliance with general data processing principles The data subject had subscribed to a newsletter of the controller. After altering his/her e-mail address, he/she continued to receive the newsletter via the old e-mail address.… NAIH ·Art. 5 ·Non-compliance with general data processing principles Personal Data Controllers IP Address Nov 18, 2020
€800,000 Carrefour Banque: Non-compliance with general data processing principles The French DPA (CNIL) imposed a fine on Carrefour Banque for violation of its obligation to process data fairly (Article 5 (1) GDPR). If a person who subscribed to the Pass card… FRANCE ·CNIL ·Art. 5 IP Address Processing Agreement Insurance Nov 18, 2020
€2,000 Comune di Collegno: Insufficient fulfilment of data subjects rights Fine for non-compliance with the right of the data subject to access to information because the municipality refused the data subjects' request for access to data from a camera… ITALY ·Garante ·Art. 12, 13, 14 Video Surveillance Personal Data Public Authority Nov 17, 2020
€1,600 Homeowners Association: Non-compliance with general data processing principles Usage of CCTV camera systems that were also monitoring public space (breach of principle of data minimization). SPAIN ·aepd ·Art. 5 Video Surveillance Audit Logs Monitoring Nov 16, 2020
€1,500 BELGIUM DPA: Non-compliance with general data processing principles The Belgian DPA (APD/GBA) imposed a fine of EUR 1,500 on a social housing company for non-compliance with several principles of the GDPR such as data processing as well as the… APD ·Art. 5, 6, 12 +3 ·Non-compliance with general data processing principles Video Surveillance Fairness & Transparency IP Address Nov 13, 2020
€12M Vodafone Italia S.p.A.: Non-compliance with general data processing principles The company was fined EUR 12,251,601 for unlawfully processing personal data of millions of customers for telemarketing purposes. The proceedings were preceded by hundreds of… ITALY ·Garante ·Art. 5, 6, 7 +7 IP Address Telecommunications Personal Data Nov 12, 2020
€900,000 Telecoms provider (1&1 Telecom GmbH): Insufficient technical and organisational measures to ensure information security Original Fine Summary: The Controller is a company offering telecommunication services. A caller could obtain extensive information on personal customer data from the company's… GERMANY ·BfDI ·Art. 32 Telecommunications IP Address Controllers Nov 11, 2020
€20,000 Gaypa s.r.l.: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 20,000 on Gaypa s.r.l.. The controller had kept a former employee's email account active and had access to the data subject's… ITALY ·Garante ·Art. 5, 12, 13 Personal Data Controllers IP Address Oct 29, 2020
€4,000 Play Orenes, S.L.: Non-compliance with general data processing principles The company used CCTV cameras outside its premises which also captured the public space resulting in a violation of the principle of data minimisation. SPAIN ·aepd ·Art. 5 Video Surveillance Retention Period IP Address Oct 28, 2020
€4,000 Organic Natur 03 S.L.: Insufficient fulfilment of information obligations Use of a membership contract containing pre-defined privacy clauses, which prevents effective negotiation and the express consent of the signing client. SPAIN ·aepd ·Art. 13 Consent IP Address Supervisory Authorities Oct 26, 2020
€20,000 Università Campus Bio-medico di Roma (Polyclinic): Non-compliance with general data processing principles In a data breach notification pursuant to Art. 33 GDPR, the data protection authority found that patients accessing their online medical reports via their smartphones could also… ITALY ·Garante ·Art. 5, 9 Notification Obligation Data Breaches Healthcare Oct 26, 2020
€200 Private Individual: Non-compliance with general data processing principles Original summary: The DPA of Saxony-Anhalt imposed a fine of EUR 200 on a private individual. The controller had taken photos of vehicles and, in some cases, their drivers and… GERMANY ·Art. 5, 32 ·Non-compliance with general data processing principles Encryption IP Address Controllers Oct 24, 2020
€54,800 Deichmann Cipőkereskedelmi Korlátolt Felelősségű Társaságnak: Insufficient fulfilment of data subjects rights The data controller denied the data subject access to the video material recorded by CCTV in a local store, with which the data subject wanted to prove that he or she had not… HUNGARY ·NAIH ·Art. 12, 15, 18 +1 Right of Access Procedures Right of Access Video Surveillance Oct 23, 2020
€15,000 Vilnius City Municipality Administration: Non-compliance with general data processing principles During the data synchronization of the Population Information System of the Municipal Administration with the databases of the State Centre for Business Registers, the personal… LITHUANIA ·VDAI ·Art. 5 Integrity and Confidentiality Principle Personal Data Professional Secrecy Oct 21, 2020
€5,000 Caja Rural San José de Nules S. Cooperativa de Crédito: Non-compliance with general data processing principles The company published information with the names and surnames of its employees, which led to the disclosure of the data subject's financial situation. SPAIN ·aepd ·Art. 5 Personal Data Employees IP Address Oct 9, 2020
€2,000 Private Person: Non-compliance with general data processing principles Usage of CCTV camera that was also capturing foreign private space of a neighbour. SPAIN ·aepd ·Art. 5, 6 Video Surveillance IP Address Processing Oct 9, 2020
€900 Café Restaurante B.B.B: Non-compliance with general data processing principles The cafe used CCTV cameras which also captured the public space outside resulting in a violation of the so called principle of data minimisation. SPAIN ·aepd ·Art. 5 Video Surveillance Retention Period IP Address Oct 9, 2020
€3,000 Avata Hispania, S.L.: Insufficient legal basis for data processing Infringement of Art. 28 (3) g) GDPR, since personal data were further processed after the controller had terminated the contractual relationship with the processor. SPAIN ·aepd ·Art. 5, 6, 28 Controllers Processors Personal Data Oct 3, 2020
€60,000 Scanshare s.r.l.: Insufficient technical and organisational measures to ensure information security According to the data protection authority, personal information about participants in a public competition had been unlawfully disclosed online. The reason for this was that, due… ITALY ·Garante ·Art. 5, 6, 9 +1 Healthcare Personal Data Controllers Sep 30, 2020
€80,000 Azienda Ospedaliera di Rilievo Nazionale 'Antonio Cardarelli' (Private Hospital): Insufficient technical and organisational measures to ensure information security According to the data protection authority, personal information about participants in a public competition had been unlawfully disclosed online. The reason for this was that, due… ITALY ·Garante ·Art. 5, 6, 13 +2 Healthcare Processors Healthcare Sep 30, 2020